Weekly Meeting 2018 Nov 28 Security Working Group

  • Slides: 10
Download presentation
Weekly Meeting 2018 Nov 28 Security Working Group edgexfoundry. org | @edgexfoundry

Weekly Meeting 2018 Nov 28 Security Working Group edgexfoundry. org | @edgexfoundry

2018 Nov 28 Security Working Group Meeting Agenda This Week’s Meeting Focus • •

2018 Nov 28 Security Working Group Meeting Agenda This Week’s Meeting Focus • • • TSC update Delhi Component Overview Delhi Demo Alain/Tingyu Upcoming meeting topics Other Questions/Topics If time allows: working discussions edgexfoundry. org | @edgexfoundry

TSC Update • Edinburgh work has begun • Starting with more detailed documentation •

TSC Update • Edinburgh work has begun • Starting with more detailed documentation • Delhi Security Demo next hour in the Security WG meeting • HW Secure storage design document review next week edgexfoundry. org | @edgexfoundry

Edge. X Security Components (Delhi) 1. 2. 3. 4. 5. 6. docker-compose up -d

Edge. X Security Components (Delhi) 1. 2. 3. 4. 5. 6. docker-compose up -d vault-worker docker-compose up -d kong-db docker-compose up -d kong-migrations docker-compose up -d kong docker-compose up -d edgex-proxy API Gateway TLS (Server Side) User Store JWT Oauth ACL Postgres. DB Vault Worker Consul (Service Discovery) Kong Migrations Kong Init Vault (Secret Store)

Edge. X Security Components (Delhi) API Gateway Security Component start order 1. 2. 3.

Edge. X Security Components (Delhi) API Gateway Security Component start order 1. 2. 3. 4. 5. 6. docker-compose up -d vault-worker docker-compose up -d kong-db docker-compose up -d kong-migrations docker-compose up -d kong docker-compose up -d edgex-proxy Note: This sequence begins after Consul is up and the previous services in the established order have been run Kong Migrations Vault Worker Master Key Long Running Process Platform Component (not security) Encrypted Unencrypted Pkisetup JWT Postgres. DB Vault (Secret Store) Vault Cert TLS (Server Side) User Store Edge. X Proxy Kong Server Cert Root Token Docker Volumes Oauth ACL Consul (Service Discovery) Vault Contents

Edge. X Security Components (Edinburgh) Security Component start order 1. docker-compose up -d vault

Edge. X Security Components (Edinburgh) Security Component start order 1. docker-compose up -d vault 2. docker-compose up -d new-securityservice 3. docker-compose up -d kong-db 4. docker-compose up -d kong-migrations 5. docker-compose up -d kong 6. docker-compose up -d edgex-proxy Note: This sequence begins after Consul is up and the previous services in the established order have been run Long Running Process Platform Component (not security) Encrypted Unencrypted (Future) Systems Mgmt Agent API Gateway Kong Migrations P Security Service Pkisetup TLS (Server Side) User Store JWT Postgres. DB Vault (Secret Store) Master Key Vault Cert Root Token Non-root Token #1 Edge. X Proxy Kong Server Cert Non-root Token #n Docker Volumes HW Encryption Oauth ACL Consul (Service Discovery) Vault Contents

Demo edgexfoundry. org | @edgexfoundry

Demo edgexfoundry. org | @edgexfoundry

Upcoming meeting topics • Delhi Security Demo • HW Secure Storage Abstraction Design •

Upcoming meeting topics • Delhi Security Demo • HW Secure Storage Abstraction Design • Code scanning edgexfoundry. org | @edgexfoundry

Other Questions/Topics • Anybody? edgexfoundry. org | @edgexfoundry

Other Questions/Topics • Anybody? edgexfoundry. org | @edgexfoundry

Working Discussions edgexfoundry. org | @edgexfoundry

Working Discussions edgexfoundry. org | @edgexfoundry